Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-43618

Опубликовано: 20 мая 2026
Источник: redhat
CVSS3: 8.1
EPSS Низкий

Описание

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.

A flaw was found in rsync. An authenticated daemon peer can exploit an integer overflow vulnerability in the compressed-token decoder. By carefully manipulating the compressed-token, a malicious sender can trigger an overflow, leading to remote memory disclosure. This allows an attacker to leak sensitive process memory contents, including environment variables, passwords, and memory pointers, which significantly weakens Address Space Layout Randomization (ASLR) and can facilitate further exploitation.

Отчет

This flaw in rsync's compressed-token decoding allows an authenticated remote attacker to trigger an integer overflow. This can lead to memory disclosure, potentially exposing sensitive information such as environment variables or heap pointers, thereby weakening Address Space Layout Randomization (ASLR) and aiding further exploitation. The vulnerability is present when rsync is configured as a daemon with compression enabled, which is the default for protocols version 30 and higher.

Меры по смягчению последствий

Disable compression on the rsync daemon by adding refuse options = compress to the rsyncd.conf file. A restart of the rsync daemon service is required for the change to take effect and may impact transfer performance.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 6rsyncAffected
Red Hat Enterprise Linux 7rsyncAffected
Red Hat OpenShift Container Platform 4rhcosAffected
Red Hat Enterprise Linux 10rsyncFixedRHSA-2026:2633216.06.2026
Red Hat Enterprise Linux 8rsyncFixedRHSA-2026:2640816.06.2026
Red Hat Enterprise Linux 9rsyncFixedRHSA-2026:2641016.06.2026
Red Hat Enterprise Linux 9rsyncFixedRHSA-2026:2641016.06.2026
Red Hat Discovery 2discovery/discovery-ui-rhel9FixedRHSA-2026:2919724.06.2026

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-190
https://bugzilla.redhat.com/show_bug.cgi?id=2469054rsync: rsync: Remote memory disclosure via integer overflow in compressed-token decoding

EPSS

Процентиль: 52%
0.0078
Низкий

8.1 High

CVSS3

Связанные уязвимости

CVSS3: 8.1
ubuntu
2 месяца назад

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.

CVSS3: 8.1
nvd
2 месяца назад

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.

CVSS3: 8.1
msrc
2 месяца назад

Rsync < 3.4.3 Integer Overflow Information Disclosure

CVSS3: 8.1
debian
2 месяца назад

Rsync version3.4.2 and prior contain an integer overflow vulnerability ...

CVSS3: 8.1
github
2 месяца назад

Rsync version 3.4.2 and prior contain an integer overflow vulnerability in the compressed-token decoder where a 32-bit signed counter is not checked for overflow, allowing a malicious sender to trigger an overflow that causes the receiver process to read and return data from outside the intended buffer bounds. Attackers can exploit this vulnerability to disclose process memory contents including environment variables, passwords, heap and stack data, and library memory pointers, significantly reducing ASLR effectiveness and facilitating further exploitation.

EPSS

Процентиль: 52%
0.0078
Низкий

8.1 High

CVSS3

Уязвимость CVE-2026-43618